Claude Code can read a repository, run commands, and edit files using models on Amazon Bedrock. A team deployment needs more than a working connection: engineers need scoped access, reliable credentials, approved models, and an audit trail.
Start by choosing direct Bedrock access, Claude Desktop with Bedrock, or self-hosted inference. The steps below cover account preparation, IAM, configuration, and the operational controls each path requires.
Quick Decision Matrix
| You need… | Choose |
|---|---|
| Claude Code in the terminal with AWS billing and governance | Direct Bedrock |
| Claude Desktop with Cowork and Code inference routed through Bedrock | Cowork on 3P with Bedrock |
| Claude apps with Anthropic-managed SaaS administration | Team / Enterprise |
| Open-source models in your VPC | Self-hosted |
| Engineering + business users together | Hybrid |
Bedrock vs. Claude Team/Enterprise: AWS-Native Control or First-Party SaaS
The choice comes down to AWS-native control versus the first-party Claude app experience. Anthropic's own deployment overview positions Claude Team/Enterprise as the best experience for most organizations, while Bedrock is the best fit for AWS-native deployments.
Claude on Amazon Bedrock
Bedrock is the right fit for organizations with AWS-native deployments that want:
- AWS billing and governance. Bedrock consumption is usage-based and appears on your standard AWS bill. AWS also offers reserved capacity, batch inference, and other pricing tiers beyond on-demand. Bedrock spend may draw down an existing AWS Enterprise Discount Program (EDP) commitment; confirm eligibility with your AWS account team, as terms vary.
- Security controls anchored in AWS. Requests are governed through AWS IAM, routed according to the selected model and inference profile, encrypted at rest and in transit, and not shared with model providers. Optional PrivateLink and VPC connectivity provide additional network-level isolation.
- Regional routing. The configured AWS Region identifies the request endpoint. Where inference runs depends on the selected model and inference profile. Validate the profile’s destination Regions before making a data-residency commitment.
- AWS application-building services. Beyond model invocation, Bedrock provides evaluation, fine-tuning, RAG (knowledge bases), agents, guardrails, and collaborative workflows through SageMaker Unified Studio.
The important caveat is now narrower: direct Bedrock access is a model/API path, not a Claude Team or Enterprise app subscription. Bedrock by itself does not include the standard Claude web, iOS, or Android apps, Claude plan administration, Anthropic-hosted conversation history, Projects, Artifacts, or Anthropic-managed connectors. Claude Desktop can now run in Cowork on 3P mode with inference routed through Bedrock, but that is a separately configured Desktop deployment with local storage, MDM/OS-managed settings, and different feature/admin parity from the standard Claude SaaS experience. If you need the simplest managed Claude app rollout with built-in collaboration and workplace connectors, compare Bedrock and Desktop 3P against Claude Team or Enterprise.
Claude Team and Enterprise (Seat-Based SaaS)
Claude Team and Enterprise plans operate outside the AWS ecosystem with a seat-based subscription model (standard and premium tiers, with optional extra usage and spend controls). What they deliver is fastest end-user adoption:
- Native web, iOS, Android, and desktop access to Claude
- Projects, Artifacts, and collaboration workflows
- Workplace connectors (Google Workspace available broadly; custom connectors also available beyond Team)
- Claude Code and Claude Cowork included
- Organizational admin, centralized billing, and security controls
- Enterprise adds SSO/SCIM, expanded retention, and advanced admin controls
Which Path Is Right?
| Dimension | Claude on Bedrock | Claude Team / Enterprise |
|---|---|---|
| Billing model | Usage-based (on-demand, reserved, batch); may draw down EDP | Seat-based subscription (standard / premium) with optional extra usage |
| Data and security | IAM, regional processing, encryption, optional PrivateLink/VPC | Anthropic-managed infrastructure with platform-level controls |
| Claude app experience | Model API plus AWS services; Desktop 3P available as a separate local deployment | Managed SaaS experience: web/mobile/desktop apps, Projects, Artifacts, connectors, and administration |
| AI development services | Evaluation, fine-tuning, RAG, agents, guardrails, SageMaker | Not applicable — user-focused SaaS |
| Best for | Engineering teams, custom integrations, AWS-native workflows | Broad organizational adoption, fastest time-to-value, non-technical users |
Many of our customers adopt both: Bedrock for engineering teams and custom applications, plus a Claude Team or Enterprise plan for business users. Elevata can help you design this hybrid approach.
Scenario 1: Claude Code with Amazon Bedrock
AWS Bedrock provides fully managed access to Anthropic's Claude models without hosting or scaling infrastructure. For teams already operating on AWS, this is the most direct path to enabling Claude Code.
Choose the endpoint before configuring access
This setup uses Invoke. For Mantle, set CLAUDE_CODE_USE_MANTLE=1 and use Mantle IDs such as anthropic.claude-sonnet-5 or anthropic.claude-opus-5; Invoke profile IDs are not interchangeable with them. Both provider flags can be enabled when routing models to different endpoints. Verify the active provider with /status. Claude Code does not use Converse. Mantle does not support Bedrock Guardrails or model invocation logging.
Use a dedicated or tightly scoped AWS account, SSO with short-lived runtime roles, and approved inference profiles. Keep account bootstrap and Marketplace permissions with the platform team. For this Invoke path, configure invocation logging, retention, log-delivery alarms, budgets, and Cost Anomaly Detection before expanding access.
Prerequisites
- An AWS account with Bedrock access enabled
- Required AWS Marketplace permissions (detailed below)
- AWS CLI v2 installed and configured for the recommended SSO path. It is optional only for narrow bearer-token/API-key experiments.
Step 1: Enable Model Access
To use Claude through Amazon Bedrock, ensure your account has the required AWS Marketplace permissions, then complete Anthropic's one-time First Time Use form. After the form, access is granted immediately, though the initial subscription/setup can take several minutes before calls succeed consistently.
- Navigate to Amazon Bedrock in the AWS Console.
- Go to Model catalog and select the desired Claude models.
- Complete Anthropic's use-case form (once per account). Access is granted immediately after submission.
- Allow a few minutes for the initial subscription to process before making your first API call.
For a single-workstation setup, run /setup-bedrock in Claude Code after completing the AWS account prerequisites. The wizard configures AWS authentication, checks model access, and saves region and model settings. For team deployment, keep the managed configuration and IAM controls described below.
Step 2: Request Service Quota Increases
Default quotas may be insufficient for team-wide usage. Request increases proactively:
| Quota | Default | Recommended Action |
|---|---|---|
| InvokeModel requests/min | Varies by model | Increase based on team size (est. 5–10 RPM per developer) |
| InvokeModelWithResponseStream | Varies by model | Proportional increase (Claude Code uses streaming) |
| Max tokens per request | Model-dependent | Verify alignment with Claude Code's context window |
Step 3: Configure IAM Permissions
Separate the one-time bootstrap/admin role from the day-to-day engineer runtime role. Anthropic's setup example includes Marketplace subscription and model-access permissions because someone has to prepare the AWS account. That does not mean engineers should carry those permissions while coding.
Bootstrap/admin role. Use this for initial account setup, model access, Marketplace subscription, Bedrock invocation logging, budgets, and guardrail configuration. Keep it with the platform or cloud team, not every developer workstation.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "BedrockAccountBootstrap",
"Effect": "Allow",
"Action": [
"bedrock:GetFoundationModel",
"bedrock:ListFoundationModels",
"bedrock:GetInferenceProfile",
"bedrock:ListInferenceProfiles",
"bedrock:PutUseCaseForModelAccess",
"bedrock:PutModelInvocationLoggingConfiguration",
"bedrock:GetModelInvocationLoggingConfiguration",
"bedrock:DeleteModelInvocationLoggingConfiguration"
],
"Resource": "*"
},
{
"Sid": "MarketplaceModelEnablement",
"Effect": "Allow",
"Action": [
"aws-marketplace:ViewSubscriptions",
"aws-marketplace:Subscribe"
],
"Resource": "*",
"Condition": {
"StringEquals": {
"aws:CalledViaLast": "bedrock.amazonaws.com"
}
}
}
]
}Engineer runtime role. This is the role developers should use day to day. It invokes only approved Claude model or inference-profile resources, discovers model/profile metadata, and reads CloudWatch metrics. Replace the account ID, Region, and model/profile IDs with the resources you have validated in your account.
{
"Version": "2012-10-17",
"Statement": [
{
"Sid": "InvokeApprovedClaudeProfilesOnly",
"Effect": "Allow",
"Action": [
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream"
],
"Resource": [
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-sonnet-5",
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-opus-5",
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-haiku-4-5-20251001-v1:0"
]
},
{
"Sid": "InvokeBackingModelsThroughApprovedProfiles",
"Effect": "Allow",
"Action": [
"bedrock:InvokeModel",
"bedrock:InvokeModelWithResponseStream"
],
"Resource": [
"arn:aws:bedrock:*::foundation-model/anthropic.claude-sonnet-5",
"arn:aws:bedrock:*::foundation-model/anthropic.claude-opus-5",
"arn:aws:bedrock:*::foundation-model/anthropic.claude-haiku-4-5-20251001-v1:0"
],
"Condition": {
"StringEquals": {
"bedrock:InferenceProfileArn": [
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-sonnet-5",
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-opus-5",
"arn:aws:bedrock:us-east-1:123456789012:inference-profile/us.anthropic.claude-haiku-4-5-20251001-v1:0"
]
}
}
},
{
"Sid": "DiscoverApprovedProfiles",
"Effect": "Allow",
"Action": [
"bedrock:GetFoundationModel",
"bedrock:ListFoundationModels",
"bedrock:GetInferenceProfile",
"bedrock:ListInferenceProfiles"
],
"Resource": "*"
},
{
"Sid": "ReadOnlyBedrockMetrics",
"Effect": "Allow",
"Action": [
"cloudwatch:GetMetricData",
"cloudwatch:GetMetricStatistics",
"cloudwatch:ListMetrics"
],
"Resource": "*"
},
{
"Sid": "DenyBearerTokenRuntimeAccess",
"Effect": "Deny",
"Action": "bedrock:CallWithBearerToken",
"Resource": "*"
},
{
"Sid": "DenyRuntimeAdministration",
"Effect": "Deny",
"Action": [
"bedrock:Create*",
"bedrock:Put*",
"bedrock:Update*",
"bedrock:Delete*",
"aws-marketplace:Subscribe",
"aws-marketplace:Unsubscribe"
],
"Resource": "*"
}
]
}This Invoke policy permits only the three approved US inference profiles and their backing models. The wildcard Region on backing models is constrained by bedrock:InferenceProfileArn, so it does not permit arbitrary direct model calls. AWS authorizes every destination Region, including destinations such as us-east-2 used by Haiku. A blanket source-only Region deny can break cross-Region inference; use the documented approved-profile exception when applying Region restrictions. Add actual application-profile ARNs to both the allowlist and condition if you use them. This is not a Mantle IAM policy or a country-only residency guarantee.
Step 4: Configure Claude Code Environment Variables
Keep the Region explicit even though current Claude Code releases can resolve it from AWS configuration. Explicit env keeps scripted rollouts deterministic and avoids mismatches between model access, invocation logging, budgets, and CloudWatch dashboards.
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_PROFILE=your-bedrock-profile
export AWS_REGION=us-east-1According to the Claude Code on Amazon Bedrock documentation, as of Claude Code v2.1.172 the Bedrock Region resolves from AWS_REGION, then AWS_DEFAULT_REGION, then the active AWS profile's region in the shared credentials/config files, then us-east-1. Older versions required AWS_REGION more strictly. Use /status to confirm the resolved Region before rollout.
This selects the AWS connection. Add the explicit model pins in Step 6 before starting a coding session.
Step 5: Configure AWS Authentication
| Method | Best For | Production stance |
|---|---|---|
| AWS SSO / IAM Identity Center | Enterprise engineers with centralized identity | Recommended default. Run aws sso login --profile=<profile> and set AWS_PROFILE. |
| Temporary role credentials | Cloud workstations, CI, or brokered access | Recommended when credentials are short-lived, scoped, and auditable. |
| IAM access keys | Legacy or narrow service-account cases | Avoid for human workstations unless there is no alternative. |
| Bedrock API keys | Exploration and prototyping | Do not use as the enterprise baseline. Deny bedrock:CallWithBearerToken in production runtime roles. |
For SSO with credential refresh, add awsAuthRefresh to your Claude Code configuration:
{
"awsAuthRefresh": "aws sso login --profile your-bedrock-profile",
"env": {
"AWS_PROFILE": "your-bedrock-profile",
"AWS_REGION": "us-east-1"
}
}Bedrock API keys are useful for fast exploration because they avoid full AWS credential setup. They are also bearer credentials. For a secure enterprise posture, prefer SSO or temporary AWS credentials, keep the runtime policy narrow, and explicitly deny bearer-token invocation from developer roles.
Step 6: Pin Model Versions
These examples pin Sonnet 5, Opus 5, and Haiku 4.5 using documented US profiles. Validate access in your account. The current Claude Code Bedrock default is Opus 5, while the bare sonnet alias still resolves to Sonnet 4.5 unless overridden. This example explicitly chooses Sonnet 5 as primary; it does not rely on an alias. Our Opus 4.8 benchmark guide remains a historical evaluation, not the current model lineup.
Sonnet 5 always uses 1M context in Claude Code; no [1m] suffix is needed. For extended Opus context on Invoke, select its [1m] variant.
export CLAUDE_CODE_USE_BEDROCK=1
export AWS_PROFILE=your-bedrock-profile
export AWS_REGION=us-east-1
export ANTHROPIC_MODEL=us.anthropic.claude-sonnet-5
export ANTHROPIC_DEFAULT_SONNET_MODEL=us.anthropic.claude-sonnet-5
export ANTHROPIC_DEFAULT_HAIKU_MODEL=us.anthropic.claude-haiku-4-5-20251001-v1:0
export ANTHROPIC_DEFAULT_OPUS_MODEL=us.anthropic.claude-opus-5Validate current availability before rollout:
aws bedrock list-foundation-models --region us-east-1 --by-provider Anthropic
aws bedrock list-inference-profiles --region us-east-1Use modelOverrides to map version-specific Anthropic model IDs to your application inference profiles. Since Claude Code v2.1.200, these mappings also apply to Anthropic IDs passed through --model or ANTHROPIC_MODEL. Replace the example ARNs with your actual profiles and authorize them in IAM:
{
"modelOverrides": {
"claude-opus-5": "arn:aws:bedrock:us-east-1:123456789012:application-inference-profile/opus-5-prod",
"claude-sonnet-5": "arn:aws:bedrock:us-east-1:123456789012:application-inference-profile/sonnet-5-prod",
"claude-haiku-4-5-20251001": "arn:aws:bedrock:us-east-1:123456789012:application-inference-profile/haiku-45-prod"
}
}Keep broad model ARNs in tutorials only. The production posture is an explicit allowlist, plus a change process for adding or retiring models.
Step 7: Enable AWS Guardrails (Optional)
Create a Guardrail in the Bedrock console, publish a version, then add the headers:
{
"env": {
"ANTHROPIC_CUSTOM_HEADERS": "X-Amzn-Bedrock-GuardrailIdentifier: your-guardrail-id\nX-Amzn-Bedrock-GuardrailVersion: 1"
}
}Cross-Region Inference
Cross-region inference profiles (model IDs prefixed with us. or eu.) allow Bedrock to route requests across configured regions to improve throughput and performance. Enable cross-region inference on your Guardrails if using these profiles.
Scenario 2: Claude Desktop on Bedrock
How to enable the setup UI
For single-machine evaluation, the official setup path is to open Claude Desktop, go to Help -> Troubleshooting -> Enable Developer mode, then Developer -> Configure third-party inference. That screen validates provider fields and exports a .mobileconfig file on macOS or a .reg file on Windows for MDM distribution. For rollout, prefer MDM over manual per-user configuration.
Minimum Bedrock configuration
Desktop supports in-app AWS SSO (version 1.6259.0+), a named AWS profile, an inferenceCredentialHelper executable that prints a bearer token, or an inferenceBedrockBearerToken. The example uses a named profile with inferenceProvider=bedrock, inferenceBedrockRegion, and inferenceModels. Validate credential refresh with your chosen method. See Desktop Bedrock setup.
Set these values in Desktop’s third-party inference configuration window. Validate the connection, then export the macOS profile or Windows registry configuration. For Linux, follow the top-level managed JSON format and file permissions in the configuration reference.
| Setting | Example value |
|---|---|
inferenceProvider | bedrock |
inferenceBedrockRegion | us-east-1 |
inferenceBedrockProfile | claude-bedrock |
inferenceModels | ["us.anthropic.claude-sonnet-5"] |
deploymentOrganizationUuid | Your organization UUID |
inferenceModels may be encoded as a JSON string for portable deployment; native macOS arrays and dictionaries are also accepted. Replace deploymentOrganizationUuid with your real organization UUID. The first configured model is the default for new Code sessions. See the configuration reference.
Base URL, PrivateLink, and Bedrock gateway
If you leave inferenceBedrockBaseUrl unset, Desktop uses the public regional Bedrock endpoint. For environments that require a private path, the key can point to a Bedrock endpoint through PrivateLink or to an LLM gateway representing Bedrock, always over https://. Even with a gateway, keep the scope Bedrock-centered: IAM, CloudTrail, region, model, quota, and cost remain the primary decisions.
Code tab: inherited configuration
Desktop supplies Code sessions with its provider, endpoint, credentials, and model list. Separate Claude Code managed settings do not replace those values. Policies such as workspace and egress restrictions follow managed-settings precedence; set parentSettingsBehavior: "merge" in Claude Code’s managed settings when those policy sources must be combined. Validate the effective policy in a real session.
Desktop 3P + Bedrock validation checklist
- Confirm the Claude Desktop version and that the third-party inference setup UI appears.
- Validate
inferenceProvider=bedrock, region, AWS profile or bearer token, and exposed models. - Confirm the AWS profile inside the sandbox resolves credentials and refreshes through SSO or a credential process.
- Test Cowork and Code separately against a small repository before opening monorepos.
- Configure
allowedWorkspaceFolders,coworkEgressAllowedHosts, disabled tools, OTel, and token limits where applicable. - Confirm CloudTrail, budgets, Bedrock metrics, and local logs before broad rollout.
Scenario 3: Self-Hosted Models on AWS
Organizations that need to run open-source or third-party models can host them within their own AWS VPC and connect Claude Code to these self-managed inference endpoints. This provides full control over model selection, data residency, and cost, but requires additional infrastructure management and comes with compatibility limitations.
Provision Inference Compute
| Instance Family | Accelerator | Use Case |
|---|---|---|
| p4d / p4de | NVIDIA A100 (40/80 GB) | Large models (70B+) |
| p5 | NVIDIA H100 | GPU inference for workloads sized and tested on H100 |
| g5 | NVIDIA A10G | Cost-effective (7B–34B) |
| inf2 | AWS Inferentia2 | Optimized inference |
Deploy an Inference Server
Your server must implement the Anthropic Messages API format (/v1/messages):
- vLLM (Recommended): Natively supports the Anthropic Messages API with high-throughput inference. vLLM has first-party documentation specifically for Claude Code via its Anthropic-compatible API.
- LiteLLM Proxy: Translation layer for models that only support OpenAI-compatible endpoints.
Compatibility Notes
- LiteLLM security: Be aware that LiteLLM versions 1.82.7 and 1.82.8 were flagged with a security advisory in Anthropic's gateway docs. Verify you are using a patched version.
- Feature parity: Parity depends on the server/proxy and model capabilities. For example, MCP tool search is disabled by default on non-first-party hosts unless the proxy forwards
tool_referenceblocks.
Networking and Security
- Inference server in a private subnet via VPN or AWS Client VPN
- Internal ALB with TLS termination
- Restrictive security groups + CloudWatch monitoring
- AWS PrivateLink for zero-trust patterns
Configure Claude Code
export ANTHROPIC_BASE_URL=https://your-vllm-endpoint.internal
export ANTHROPIC_AUTH_TOKEN=your-auth-tokenBest Practices for Production
Application Inference Profiles
Use Bedrock application inference profiles for tagged cost tracking and CloudWatch metrics by team, project, or environment. This provides granular visibility that simple Cost Explorer tags cannot. Use them later for per-team and per-project attribution once the initial rollout is stable.
Prompt Caching
Claude Code is a strong fit for Bedrock prompt caching, which can significantly reduce latency and costs for repetitive system context and codebase content. Check regional availability, as prompt caching may not be available in all regions.
Enterprise LLM Gateway
For centralized authentication, rate limiting, and cost controls, you can deploy an LLM Gateway in front of Bedrock via ANTHROPIC_BEDROCK_BASE_URL. If the gateway or a self-hosted model path bypasses Bedrock runtime invocation, implement equivalent centralized request/response logging, identity attribution, retention, and access controls because native Bedrock invocation logging no longer covers the full path.
Observability and Audit
Do not treat local Claude Code OpenTelemetry as the audit source of truth. It is useful for adoption, latency, UX, terminal/tool metrics, and developer-experience analysis, but it cannot be required from every engineer terminal and it does not replace AWS-side evidence.
The production audit baseline is Bedrock model invocation logging to CloudWatch Logs and/or S3, plus CloudTrail and AWS billing/cost telemetry. CloudTrail records Amazon Bedrock API activity, but prompt and response capture requires Bedrock invocation logging. For production, use CloudWatch Logs for operational review and S3 for long-term retention and large-payload delivery. Large payloads, image data, and document data may be delivered to S3, so the log bucket is sensitive production data and needs its own access review.
There is also a hard boundary: AWS model invocation logging is currently supported for calls through the bedrock-runtime endpoint, including InvokeModel and InvokeModelWithResponseStream. AWS notes that calls through other endpoints, such as the Responses API on bedrock-mantle, are not currently captured by invocation logging. If you use Mantle, a gateway, or self-hosted models, design equivalent logging before calling the rollout auditable.
IAM Policy Guardrails
- Do not give engineers
aws-marketplace:Subscribein day-to-day runtime roles. - Do not give engineers Bedrock logging, model-access, or admin configuration permissions in runtime roles.
- Prefer a runtime allowlist of approved inference profiles and model IDs.
- Deny requests from unapproved source Regions while preserving narrowly scoped exceptions for approved inference-profile destinations. Restrict
bedrock:CallWithBearerToken, Bedrock administration, and Marketplace subscribe/unsubscribe according to the runtime policy.
Terraform and State
Keep infrastructure code separate from helper code and templates. Put Bedrock logging, budgets, profiles, IAM, and guardrails under infra/bedrock; bootstrap the state backend separately under infra/state-backend. The state backend should use S3 versioning, SSE-KMS encryption, Block Public Access, and native S3 state locking with use_lockfile = true on supported Terraform versions. HashiCorp documents DynamoDB locking as deprecated; treat existing DynamoDB locking as a legacy configuration to migrate. Keep Terraform state and tfvars out of git.
Cost and Credits
Sonnet 5 Standard rates are $2/$10 globally or $2.20/$11 in supported commercial geographies, per million input/output tokens; Opus 5 is $5/$25 or $5.50/$27.50 respectively. AWS lists Priority and Flex as unsupported for these models. Keep ANTHROPIC_BEDROCK_SERVICE_TIER=default. Check routing-specific prices; Anthropic Marketplace charges appear under the model provider in Cost Explorer.
Do not assume promotional credits or AWS funding cover every path. Confirm whether Bedrock, API Gateway, CloudWatch Logs, S3, NAT, and any gateway usage are covered before rollout. Create a Bedrock-specific budget, a total account budget, and an anomaly subscription. Measure value as cost per successful task, not only token spend.
Security and Compliance
The model and effective policy determine retention. Fable 5/5.1 require AWS review and may retain content for up to 30 days within AWS, without sharing it with the model provider. Customer-enabled logs need separate controls. See Bedrock data retention.
Enable CloudTrail, Bedrock invocation logging, log-retention controls, KMS encryption, and access reviews for every log destination. Use Guardrails where content filtering is required, but treat them as one control in the request path, not as a substitute for IAM, logging, and approval gates. For self-hosted or gateway-backed models, implement inference-server access logging and centralized request/response capture before production use.
Troubleshooting
- Region issues:
aws bedrock list-inference-profiles --region your-region - "On-demand throughput isn't supported" error: Use an inference profile ID rather than a base model ID.
- Credential expiry: Configure
awsAuthRefreshfor automatic re-authentication. - Self-hosted endpoint: Must implement
/v1/messages. Use LiteLLM Proxy (patched version) for OpenAI-only endpoints. - Desktop does not launch in Bedrock mode: confirm
inferenceProvider=bedrock, valid credentials,inferenceBedrockRegion, and aninferenceModelsvalue encoded correctly for the deployment platform. - Cowork works but Code does not follow the same policy: validate the Code tab separately and distribute Claude Code
managed-settings.jsonwhen you need to pin policies for coding sessions.
FAQ
What infrastructure do I need to deploy Claude Code on AWS?
At minimum, you need an AWS account with Bedrock access or a private Anthropic-compatible inference endpoint, IAM permissions for model access and Marketplace subscription, explicit region and network configuration, and operational controls such as model pinning, logging, and guardrails.
Does Bedrock include Claude web?
Not as the standard SaaS experience. Bedrock provides the model API and AWS development services; Claude web/iOS/Android apps, plan administration, hosted history, Projects, Artifacts, and managed connectors remain part of Claude Team and Enterprise plans. What changed is Desktop: Claude Desktop can use Bedrock in Cowork on 3P mode, with inference on Bedrock, local storage, and MDM/OS-managed configuration.
Can Claude Desktop now use Bedrock without sending conversations to Anthropic infrastructure?
Yes, for Cowork on 3P with inferenceProvider=bedrock, Anthropic documents that prompts, responses, files, and tool outputs are sent to the configured inference endpoint and stored on the local device, not Anthropic first-party infrastructure. Still, crash reports, analytics, updates, OTel, egress, and local policies need to be configured according to the organization’s security profile.
Do I need model access approval?
For Runtime, complete Anthropic’s one-time use-case form with the required Marketplace permissions. Initial subscription processing can take up to 15 minutes. Mantle has a separate access path and does not require the Runtime FTU form; confirm model access for your account and endpoint. See AWS model access.
Are Bedrock API keys safe for production?
Bedrock API keys can be useful for exploration, but they are not recommended for human production workstation use. Prefer SSO or temporary role credentials, and deny bedrock:CallWithBearerToken in runtime roles unless a narrowly approved exception exists.
What breaks with self-hosted models?
Feature parity depends on the server/proxy and model capabilities. The best-documented caveat is MCP tool search: it is disabled by default on non-first-party hosts unless the proxy forwards tool_reference blocks. Specific LiteLLM versions (1.82.7–1.82.8) have known security advisories.
How Elevata Can Help
Setting up Claude Code is just the beginning. As an AWS Advanced Tier Services Partner with the AWS Generative AI Competency, Elevata helps organizations build the complete AI-powered development platform on AWS.
- Claude Code and Claude Cowork on Amazon Bedrock deployment — end-to-end setup for Bedrock, Claude Desktop 3P, Cowork on 3P, and self-hosted scenarios, including IAM, MDM, managed settings, AWS profiles, Code-tab controls, and onboarding automation.
- AI infrastructure — GPU sizing, inference optimization, application inference profiles, prompt caching, Bedrock invocation logging, OTel enrichment, and cost/usage dashboards.
- Hybrid plan design — deciding where Bedrock and Claude Team/Enterprise each fit and building the integrations.
- Elevata Orbit — on-demand senior AWS engineers for setup, optimization, and ongoing operations.
Contact us at elevata.io to discuss your Claude Code deployment, AI strategy, or AWS infrastructure needs.





